What Decide means
Decide is where a CSISC Executive Cyber Leader earns their keep before a single control gets touched. It's the moment someone with real authority — not a spreadsheet, not a generic industry benchmark — looks at the organisation's actual risk and says, in writing, what matters and what doesn't. Most organisations skip this step entirely. They buy tools, write policies, and run audits without ever having had the conversation about risk appetite, so security ends up being decided implicitly, by whichever supplier called last, rather than deliberately, by the people accountable for the business.
This is also the directive that closes the loop. Every cycle through Discover, Direct, Defend and Debrief eventually comes back to Demonstrate, and what the board learns from Demonstrate reshapes the next Decide. Risk appetite isn't set once and forgotten — it's revisited every reporting cycle, as the business, the threat landscape, and the budget all shift.
The board question
What your board should be able to answer at this stage
“Who is deciding what level of risk this organisation is willing to accept?”
In practice
What good looks like
- A named individual — not a committee, not “IT” — is accountable for cyber risk decisions
- A written risk appetite statement exists, and it's specific enough to actually guide a yes or no
- Budget is allocated against prioritised risks, not against whichever vendor pitched hardest
- The board can say, without hesitating, what level of disruption the business could tolerate
Where this shows up